CVE-2025-65494: Null Pointer Dereference
Published Nov 24, 2025
·Updated
NULL pointer dereference in getsanorcnfromcert() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes skGENERALNAMEvalue() to return NULL.
Affected Software
2 affected components
OISM libcoap
libcoap libcoap=4.3.5
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65494?
CVE-2025-65494 is classified as a vulnerability that can lead to denial of service.
2
How do I fix CVE-2025-65494?
To fix CVE-2025-65494, upgrade to a patched version of OISM libcoap that resolves the NULL pointer dereference issue.
3
What type of attack does CVE-2025-65494 facilitate?
CVE-2025-65494 allows remote attackers to exploit the vulnerability via crafted X.509 certificates.
4
In which component is CVE-2025-65494 found?
CVE-2025-65494 is found in the get_san_or_cn_from_cert() function in src/coap_openssl.c of OISM libcoap.
5
What can be the impact of CVE-2025-65494?
The impact of CVE-2025-65494 is a denial of service condition resulting from a NULL pointer dereference.